4 ms·
While I agree 1000 is hilariously low for this, worth is hard to quantify. Do you pay what it could theoretically cost your company? the amount the top bidding
by CookieCrisp 1mo ago
While I agree 1000 is hilariously low for this, worth is hard to quantify. Do you pay what it could theoretically cost your company? the amount the top bidding bad actor would be willing to pay?
- teravor 1mo agoideally, an auction and the vendor or a government can bid against malicious actors (which can also be a government). hard to set up though.
- 27183 1mo agoit seems unlikely google's lawyers would go for this
- teravor 1mo agowell that's why setting it up is hard, because you would want to do it in a way that what they want doesn't matter.
- aeonik 1mo agoMaybe some code is so important and heavily trafficked it becomes a public works project, and various legs can bid for pieces of the project, line how all infrastructure works.
- eru 1mo agoWhat kind of auction would you like to run? Remember that you can sell the same vulnerability to multiple people: it's software you can copy.
- Barbing 1mo agoMaybe needs a Good-Guy-Buy-It-Now w/instant delivery at a fair price. (OK that’s kind of a threat—you’re running an auction and you have the price the corp has to pay to avoid the auction ending.) $1k is so dumb and the fact we’re discussing auctions is proof (hello, Sundar, what you doing over there?). Guess this will change after the next e.g. nationwide hospital ransomware by a hacker who publicly laments bounty rates, if the news cycle accommodates the story long enough.
- eru 29d ago> Guess this will change after the next e.g. nationwide hospital ransomware by a hacker who publicly laments bounty rates, if the news cycle accommodates the story long enough. Negotiating with terrorists or black mailers is a bad idea.
- Barbing 28d agoAgreed. Paying security researchers fair rates is a good idea though right? Keeps future researchers honest?
- eru 26d agoMaybe. But as soon as they threaten to sell it to the baddies or use it for ransomware themselves, I would cease all communication and negotiation. The legitimate threat the researcher has is to disclose to the general public. (And to disclose the next bug to the general public, if there's no good payment.)
- quotemstr 1mo agoYou let the market decide. Google could purchase the bugs on the same market blackhats do.
- jsw97 1mo agoIn the past I would have thought this would incentivize finding bugs that might never be found. However it is now clear that all bugs that can be found will be found. So this makes a ton of sense.
- eru 1mo ago> In the past I would have thought this would incentivize finding bugs that might never be found. Isn't that a good thing? > However it is now clear that all bugs that can be found will be found. So this makes a ton of sense. If Google can find all the bugs nowadays, presumably with AI, why still pay a bug bounty? At least by this logic, bug bounties make less sense now.
- deleted 1mo ago[deleted]
- tptacek 1mo agoGoogle directly competes with the grey market for vulnerabilities. They are competitive in a bunch of different directions: * They pay for vulnerabilities without reliable exploits (more for vulnerabilities that are demonstrably reliable). * They don't require you to actually build a reliable exploit chain. * They pay up front, not in tranches. * They work with essentially all comers, unlike the grey market, where you're generally subcontracting to sell your first few.
- altairprime 1mo agoThe discount Google is getting on bounties versus internal spend is easy to estimate: # assumed to be $0.5mil USD or greater A := What quantity of salaries-and-benefits and AI-dollars does Google spend on zero-day research? # assumed to be greater than zero B := How many full sandbox RCEs are they *hoping* to discover per year with that budget? # $/RCE budgeted spend C := A ÷ B # $/bounty D := $1000 USD # % discount per bounty relative to in-house spend E := (C - D) / C While we lack the data to be sure, it is reasonable to estimate that they're getting a discount of 90% or better versus internal spend on this bounty payment, if one assumes that they do not have many sandbox RCEs left undiscovered. It's unclear whether that assumption holds, but with only a single researcher at an assumed $0.5mil/year (all-inclusive after pay, stock, and benefits) is enough to support the plausibility of that 90% figure, before accounting at market rates for their internal use of the house AIs. So, the most likely case is that they're greedy and miserly, and hope we don't do the math. However I recognize that there are judgment calls to be made here. Either their internal spending finds hundreds of RCEs per year, or they're significantly discounting bounty payments versus their actual worth, or they're negligent in budgeting for RCE discovery at all, or they assign zero value to the security of the Chromium platform underpinning Edge, Electron, et al. All of these are bad in different ways; one hopes a competent tech reporter actually pursues this line of questioning with them!
- cogman10 29d ago> or they're negligent in budgeting for RCE discovery at all, or they assign zero value to the security of the Chromium platform underpinning Edge, Electron, et al I generally agree, but a 3rd explanation is they figure that too generous a bounty will flood them with reports of minor issues making major ones harder to see (and costing time and money to verify that could be spent looking for security issues).
- altairprime 29d agoHaving previously worked near a bounty program, I can confirm that they are regardless flooded with people fishing for bounties, even before AI, no matter how cheap the bounty may be — people will grift anything with the most pathetic skript kiddie attempts possible to try and pad their resume with a hit, and bounties that pay $0 are more valuable than pull requests that pay $0.